CWE-862
CVEs classified under CWE-862, newest first.
1332 CVEsRSS
CVE-2026-70547Medium· 4.3An authenticated user without repository read permission may access package metadata under specific conditions.
An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-69107Medium· 5.9An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-63300Critical· 9.9An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security res…
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security res…
CVE-2026-73287Medium· 5.4RustFS is a distributed object storage system built in Rust
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without authorize_operation for S3Act…
CVE-2026-73265Medium· 6.5RustFS is a distributed object storage system built in Rust
RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals wi…
CVE-2026-47233Medium· 6.5Admidio is an open-source user management solution
Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied to the sibling `case 'field_delete':` h…
CVE-2026-47226Medium· 6.5Admidio is an open-source user management solution
Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can permanently delete files from folders where they have only view access. The authorizati…
GHSA-xx34-6cjg-prh8Critical· 8.6Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
GHSA-mxjf-vfmv-qfm6Medium· 5.8Duplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
Duplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
CVE-2026-68758Medium· 6.5A low-privileged authenticated user may access restricted support information under specific conditions.
A low-privileged authenticated user may access restricted support information under specific conditions.
CVE-2026-65938Medium· 4.3In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
CVE-2026-65926Low· 3.1An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.
CVE-2026-68754Medium· 6.5A repository publisher without delete permission may modify protected package content under specific conditions.
A repository publisher without delete permission may modify protected package content under specific conditions.
CVE-2026-68753Medium· 5.3An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
CVE-2026-66380Medium· 4.3An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
CVE-2026-66379Medium· 4.3An authenticated user may view private Puppet module metadata without repository read access.
An authenticated user may view private Puppet module metadata without repository read access.
CVE-2026-66378Medium· 4.3An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVE-2026-66377Medium· 5.3An unauthenticated user may access restricted repository information under specific conditions.
An unauthenticated user may access restricted repository information under specific conditions.
CVE-2026-66375High· 8.1A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
CVE-2026-64954High· 8.2Velociraptor allows scheduling new collections via VQL queries in notebooks
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which reset…
CVE-2026-18652Medium· 6.5Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowi…
Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowi…
CVE-2026-72805Medium· 5.8SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata
SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata. Anonymous readers or publish RoleRead…
CVE-2026-72797Medium· 5.8SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering. Anonymous read…
CVE-2026-72789High· 8.6SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypte…
CVE-2026-73301Medium· 4.3Budibase is an open-source low-code platform
Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate te…
CVE-2026-69115Medium· 6.5OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-only management API endpoints by submitting POST requests with a regular user bearer token to /user/get_users, /user/g…
OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-only management API endpoints by submitting POST requests with a regular user bearer token to /user/get_users, /user/g…
CVE-2026-69113Medium· 5.4Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on any private video without permission by supplying an arbitrary videoId in the request b…
Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on any private video without permission by supplying an arbitrary videoId in the request b…
CVE-2026-73249High· 7.5calibre is an e-book manager
calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.ch…
CVE-2026-48763High· 8.2TypeBot is a chatbot builder tool
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a…
CVE-2026-48495High· 7.1TypeBot is a chatbot builder tool
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptog…